exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 1 question 11 discussion

Actual exam question from Microsoft's SC-100
Question #: 11
Topic #: 1
[All SC-100 Questions]

Your company has a third-party security information and event management (SIEM) solution that uses Splunk and Microsoft Sentinel.
You plan to integrate Microsoft Sentinel with Splunk.
You need to recommend a solution to send security events from Microsoft Sentinel to Splunk.
What should you include in the recommendation?

  • A. a Microsoft Sentinel data connector
  • B. Azure Event Hubs
  • C. a Microsoft Sentinel workbook
  • D. Azure Data Factory
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BPQ
Highly Voted 2 years, 8 months ago
if data need to go to splunk then event hub. https://www.splunk.com/en_us/blog/platform/splunking-azure-event-hubs.html
upvoted 46 times
prabhjot
2 years, 8 months ago
agree as i donot see any Splunk data connector in Sentinel and also no Azure Http PI connector in Sentinel
upvoted 6 times
...
xping85
1 year, 9 months ago
https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/azure-sentinel-side-by-side-with-splunk-via-eventhub/ba-p/2307029
upvoted 3 times
...
...
yaza85
Highly Voted 2 years, 3 months ago
Selected Answer: B
B. Data connectors are for receiving data not to send data
upvoted 11 times
nils241
1 year, 3 months ago
Thats the point .Read the Question "...send security events FROM Microsoft Sentinel TO Splunk." So it cant be an data connector
upvoted 1 times
...
...
Dev21
Most Recent 9 months ago
Azure Event Hub is the correct answer.
upvoted 1 times
...
hondo1997
10 months ago
hub de eventos do azure
upvoted 1 times
...
DivG
1 year, 2 months ago
Azure Event Hub is the correct answer. https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/azure-sentinel-side-by-side-with-splunk-via-eventhub/ba-p/2307029
upvoted 2 times
...
RickySmith
1 year, 3 months ago
Selected Answer: B
Azure Event Hubs. "to send security events from Microsoft Sentinel to Splunk" https://www.splunk.com/en_us/blog/platform/splunking-azure-event-hubs.html - Event Hubs can process data or telemetry produced from your Azure environment. They also provide us a scalable method to get your valuable Azure data into Splunk! https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/azure-sentinel-side-by-side-with-splunk-via-eventhub/ba-p/2307029 - Another option would be to implement a Side-by-Side architecture with Azure Event Hub. Not a Microsoft Sentinel data connector - Microsoft Sentinel Add-On for Splunk allows Azure Log Analytics and Microsoft Sentinel users to ingest security logs 'from' Splunk platform using the Azure HTTP
upvoted 1 times
...
TomasValtor
1 year, 5 months ago
Answer B Preparation : The following tasks describe the necessary preparation and configurations steps. Onboard Azure Sentinel Register an application in Azure AD Create an Azure Event Hub Namespace Prepare Azure Sentinel to forward Incidents to Event Hub Configure Splunk to consume Azure Sentinel Incidents from Azure Event Hub Using Azure Sentinel Incidents in Splunk
upvoted 1 times
...
XtraWest
1 year, 5 months ago
Selected Answer: B
B. Events Hubs | Azure Event Hubs can be used to buffer and route events between Microsoft Sentinel and Splunk. This option provides scalability and reliability in handling high volumes of security events.
upvoted 1 times
...
ConanBarb
1 year, 7 months ago
Selected Answer: B
I must say that I do think it's strange and unusual for a Microsoft exam to have a scenario where data is going from their own product to a third party's. It's to my experience always the other way. Therefor I suspect that it could be a typo saying "from Sentinel to Splunk". It's more likely to be "to Sentinel from Splunk". I.e. Sentinel Data connectors If appearing on a test make sure to read carefully...
upvoted 2 times
...
sherifhamed
1 year, 7 months ago
Selected Answer: A
To send security events from Microsoft Sentinel to Splunk, you should use a Microsoft Sentinel data connector. Data connectors in Microsoft Sentinel are used to export security events and logs to external systems, and Splunk is a supported destination for these connectors. So, the correct recommendation is: A. a Microsoft Sentinel data connector
upvoted 5 times
...
ServerBrain
1 year, 8 months ago
Rule of thumb - always go with most votes!!
upvoted 2 times
...
WRITER00347
1 year, 9 months ago
To send security events from Microsoft Sentinel to Splunk, you would typically use Azure Event Hubs as the messaging service that can integrate with both solutions. Azure Event Hubs can be used to collect and stream event data into various services, and it's suitable for integration with third-party SIEM solutions like Splunk. So, the correct answer to include in the recommendation would be: B. Azure Event Hubs.
upvoted 1 times
...
MaciekMT
1 year, 9 months ago
Selected Answer: B
my 2 cents: given the options to chose from - I would go for event hub. I would imagine the best solution in this case would be Microsoft Graph Security API Add-On for Splunk https://splunkbase.splunk.com/app/4564
upvoted 1 times
...
ariania
1 year, 11 months ago
Selected Answer: B
Indeed B
upvoted 1 times
...
zellck
1 year, 11 months ago
Selected Answer: B
B is the answer. https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/azure-sentinel-side-by-side-with-splunk-via-eventhub/ba-p/2307029
upvoted 1 times
...
Jay_G
2 years ago
https://learn.microsoft.com/en-us/azure/defender-for-cloud/export-to-siem#stream-alerts-to-qradar-and-splunk
upvoted 1 times
...
Hashamkhan
2 years ago
There is a distinction between data connectors for receiving ( <a href="https://reminiapk.org/">ai</a>) data and data connectors for sending data
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago